Earlier quoted context omitted.
why not make the point with at least a self signed cert?
99% of visitors wouldn't get the intended point - they'd think he's pro-cert, but forgot to renew it or something.
Whenever I visit a HTTP-only site, I assume the administrator is either old and does not understand how to set up SSL, or it's an unmaintained/forgotten web server that hasn't been touched in about a decade.